CybersecurityFramework

CMMC

Cybersecurity Maturity Model Certification

The Cybersecurity Maturity Model Certification (CMMC) Assessment Guide defines how organizations are evaluated for compliance with cybersecurity requirements when working with the U.S. Department of Defense. It outlines assessment methods, evidence expectations, and control validation aligned with standards like NIST SP 800-171. The guide ensures consistent and rigorous verification of an organization’s ability to protect sensitive information.

Overview

The Cybersecurity Maturity Model Certification (CMMC) Assessment Guide provides detailed criteria and methodologies used by assessors to evaluate whether defense contractors meet required cybersecurity controls for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It supports a tiered assessment model aligned with three maturity levels, defining specific practices, objectives, and evidence needed to demonstrate compliance with standards such as NIST SP 800-171. The guide ensures consistency and rigor in assessments by outlining how controls are verified, including documentation review, interviews, and testing procedures. It is used to validate that organizations have effectively implemented required safeguards as a condition for participating in U.S. Department of Defense contracts.

Related in Cybersecurity

CybersecurityStandard

PPG 511 — Prudential Practice Guide 511 - Remuneration

Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance.

Australian Prudential Regulation Authority (APRA) • Australia • v30 November 2009

View details
CybersecurityGuideline

NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

National Institute of Standards and Technology (NIST) • United States

View details
CybersecurityRegulation

Dubai ISR — Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Dubai Government • Dubai • v3

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australian • v2 July 2018

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call